dogwood.values#

Python value, event, response, and fallback authorizer types.

These classes mirror the names in dogwood_language so code written against dogwood-py follows the Rust API shape. Schema-backed production behavior should use dogwood.native; the classes here also power the temporary schema-less fallback path.

class dogwood.values.Decision[source]#

Authorization decision.

Rust mapping: dogwood_language::Decision.

ALLOW = 'Allow'#
DENY = 'Deny'#
__new__(value)#
class dogwood.values.Entity[source]#

Cedar entity uid wrapper.

Rust mapping: Dogwood events ultimately carry Cedar entity UIDs for principal/resource scope.

ty: str#
id: str#
classmethod parse(text)[source]#
Parameters:

text (str)

Return type:

Entity

class dogwood.values.DogwoodRuleRef[source]#

Reference to an originating Dogwood rule.

Rust mapping: dogwood_language::DogwoodRuleRef.

rule_index: int#
cedar_policy_id: str#
class dogwood.values.Diagnostics[source]#

Decision diagnostics.

Rust mapping: dogwood_language::Diagnostics. Native diagnostics are not fully exposed through PyO3 yet; the fallback stores determining rule refs and errors.

reason: tuple[DogwoodRuleRef, ...] = ()#
errors: tuple[str, ...] = ()#
class dogwood.values.Response[source]#

Authorization response.

Rust mapping: dogwood_language::Response returned by Authorizer::is_authorized for decision-kind events.

decision: Decision#
diagnostics: Diagnostics#
allowed()[source]#

Return true when decision is Decision.ALLOW.

Return type:

bool

class dogwood.values.Event[source]#

Dogwood event.

Rust mapping: dogwood_language::Event. An event generalizes a Cedar request with a first-class kind such as request or response. Decision kinds are defined by the Dogwood event schema; the default schema makes request a decision kind and response history-only.

action_name: str#
kind_name: str#
ts: int = 0#
scope_principal: Entity | None = None#
scope_resource: Entity | None = None#
logged: dict[str, Any]#
request_ctx: dict[str, Any]#
entities: dict[str, dict[str, Any]]#
classmethod builder(action, kind)[source]#

Start building an event.

Rust mapping: Event::builder(action, kind).

Parameters:
  • action (str)

  • kind (str)

Return type:

EventBuilder

property action: str#
property kind: str#
timestamp()[source]#

Return the event timestamp.

Rust mapping: Event::timestamp().

Return type:

int

principal()[source]#

Return the request principal, if this event carries request scope.

Rust mapping: Event::principal().

Return type:

str | None

resource()[source]#

Return the request resource, if this event carries request scope.

Rust mapping: Event::resource().

Return type:

str | None

field(group, name)[source]#

Read one logged event field.

Rust mapping: Event::field(group, name).

Parameters:
  • group (str)

  • name (str)

Return type:

Any | None

fields(group)[source]#

Iterate logged event fields in a group.

Rust mapping: Event::fields(group).

Parameters:

group (str)

Return type:

Iterable[tuple[str, Any]]

field_path(path)[source]#
Parameters:

path (list[str] | tuple[str, ...])

Return type:

Any | None

request_context_path(path)[source]#

Read a value from the Cedar request context path.

Parameters:

path (list[str] | tuple[str, ...])

Return type:

Any | None

class dogwood.values.EventBuilder[source]#

Builder for Event.

Rust mapping: dogwood_language::EventBuilder.

timestamp(ts)[source]#

Set the event timestamp.

Rust mapping: EventBuilder::timestamp.

Parameters:

ts (int)

Return type:

EventBuilder

principal(uid)[source]#

Set request principal scope.

Rust mapping: EventBuilder::principal.

Parameters:

uid (str)

Return type:

EventBuilder

resource(uid)[source]#

Set request resource scope.

Rust mapping: EventBuilder::resource.

Parameters:

uid (str)

Return type:

EventBuilder

field(group, name, value)[source]#

Add one logged event field.

Rust mapping: EventBuilder::field.

Parameters:
  • group (str)

  • name (str)

  • value (Any)

Return type:

EventBuilder

logged_group(group, value)[source]#

Add a full logged event field group.

Parameters:
  • group (str)

  • value (dict[str, Any])

Return type:

EventBuilder

request_context(group, name, value)[source]#

Add one Cedar request context field.

Parameters:
  • group (str)

  • name (str)

  • value (Any)

Return type:

EventBuilder

request_context_group(group, value)[source]#

Add a full Cedar request context group.

Parameters:
  • group (str)

  • value (dict[str, Any])

Return type:

EventBuilder

build()[source]#

Return the constructed event.

Rust mapping: EventBuilder::build.

Return type:

Event

class dogwood.values.Authorizer[source]#

Stateful fallback authorizer.

Rust mapping: dogwood_language::Authorizer. The native equivalent is dogwood.native.NativeAuthorizer; this class is the temporary schema-less Python fallback.

history: list[Event]#
is_authorized(event)[source]#

Authorize one event and record it in history.

Rust mapping: Authorizer::is_authorized(&event) -> Option<Response>. Returns None for history-only events. In the fallback, only request is treated as a decision kind.

Parameters:

event (Event)

Return type:

Response | None